Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Disallow RDP access to certain accounts which are part of Domain Admins

Posted on 2013-11-10
4
Medium Priority
?
388 Views
Last Modified: 2014-02-26
Hi,

We have several 100 servers and we have few accounts used as a service account on these servers.  It is a requirement by the application for these service accounts to be member of Domain Admins Group.

I would like to prevent some of the service accounts RDP access on all our servers.  What is the quickest way of accomplishing this?  Can I do something on the user level like Deny RDP Access etc.??

Help please.
0
Comment
Question by:fais79
  • 2
4 Comments
 
LVL 53

Expert Comment

by:Will Szymkowski
ID: 39638096
You can do this via GPO. Remember that this change can be reverted back with this account as it is a domain admin account.

Not recommend but can be done via GPO.

Deny RDP access - http://technet.microsoft.com/en-us/library/cc737453(WS.10).aspx

Will.
0
 
LVL 24

Accepted Solution

by:
Sandeshdubey earned 2000 total points
ID: 39638102
0
 
LVL 57

Expert Comment

by:McKnife
ID: 39638620
Before we leave it unquestioned... :)
Why would you need to have those accounts setup as domain admins? Normally, you would use service accounts and assign/delegate just some privileges to them and not the whole lot.
0
 
LVL 57

Expert Comment

by:McKnife
ID: 39877784
Please respond or finalize it, this question is growing old :)
0

Featured Post

Keep up with what's happening at Experts Exchange!

Sign up to receive Decoded, a new monthly digest with product updates, feature release info, continuing education opportunities, and more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Here's a look at newsworthy articles and community happenings during the last month.
How to deal with a specific error when using the Enable-RemoteMailbox cmdlet to create a mailbox in the cloud-based service, for an existing user in an on-premises Active Directory.
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.
Suggested Courses

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question